stop your breeches
June 20, 2022

stop your breeches

Daniel Knights | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

Splunk Enterprise Security is an awesome tool to start a security team. alerts and places for them to investigate security incidents. we use it at our client sites to start them on their journey to a CSOC. this product allows the team to work together to solve issues on the network. we use it to monitor all aspects of the network
  • alerts
  • dashboards
  • network overview
  • security overview
  • better alert suppression
  • have a way to alert all users to an event
  • MTTR is much better
  • MTTD is now a thing before we had nothing
Splunk is able to be scaled infinitely with both on-prem or cloud or both. so far it can do whatever we throw at it

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Yes

Are you happy with Splunk Enterprise Security (ES)'s feature set?

Yes

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

we have used this to alert us when our network is under attack. or a user is doing something they should not be doing. Splunk Enterprise Security is well suited for Security Intelligence collection and investigation. our CSOC team uses it each day to track down problem users and security incidents. our clients love the overview dashboards it gives

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
10
Correlation
10
Event and log normalization/management
10
Deployment flexibility
10
Integration with Identity and Access Management Tools
10
Custom dashboards and workspaces
10
Host and network-based intrusion detection
8
Log retention
10
Data integration/API management
8
Rules-based and algorithmic detection thresholds
8
Reporting and compliance management
9
Incident indexing/searching
9